Google collects face data now – what it means and how to opt out
cnet.com
cnet.com
>The Biometric Information Privacy Act (BIPA) was passed by the Illinois General Assembly on October 3, 2008. Codified as 740 ILCS/14 and Public Act 095-994, the BIPA guards against the unlawful collection and storing of biometric information.[1] When Illinois passed the law in 2008, it became the first state to regulate the collection of biometric information.[2] Washington and Texas have since passed similar laws.[3] However, the BIPA remains the only law that allows private individuals to file a lawsuit for damages stemming from a violation
https://en.wikipedia.org/wiki/Biometric_Information_Privacy_...
Edit: my conspiracy theory is that the tech industry's lobbyists are pushing for legislation on privacy at the federal level because they know such a law would be more watered down than what states would pass.
And almost certainly much weaker than IL's current laws in protecting privacy in this regard.
There are legal technicalities about if the Google case is appealable on that basis, and what the result of the next similar lawsuit will be.
If the law can't be used to protect us what measures remain available? Storming Google's data centers by force? The legal system is supposed to be the acceptable option so mobs and violence aren't all we have. Eliminate legal recourse and what's left?
The simple fact is that the digital world is a new world, and we need new law. Old law simply doesn't extrapolate.
It's short and pretty clear. the words harm, injury, abuse etc are nowhere to be found. Google violated the law as written but the judge didn't even address that because he decided they had no right to complain in the first place.
It reminds me of the case journalists made against the US government after it came to light that they were illegally wiretapping them. The fact that the government's mass surveillance program was exposed wasn't enough for the courts who decided that because the journalists who took it to court couldn't prove that specific instances of wiretapping occurred (information they couldn't possibly have because it's secret) they had no right to sue and the fact that wiretaps were put in place without a warrant wasn't even addressed.
"Google" is not an entity -- it's composed of people, who make decisions and enable the things that Google does.
Don't hire them. Don't associate with them.
They're working for a company that, at this point, is obviously doing harm to the world. That's a choice they have the freedom to make. We have the freedom not to associate with people who make that choice.
Note that this advice is specific to non-visa-limited people in high-demand occupations, like other software engineers. They have a choice.
It is. It's a legal entity called a corporation
> Don't hire them. Don't associate with them.
You no longer have a choice to opt out of google invading your privacy. The websites you visit everyday are letting google track you. The websites I use for my work are tracking me via google. My employer also requires chrome for some tasks which allows google to track what I do. I've even seen government websites using google trackers. You just can't escape google on the internet. Google is so pervasive even ARIN is allowing google to track people who go to their site.
Google is quickly intruding on offline public spaces as well.
When a user-hostile company becomes impossible to escape the only option left is to regulate it to limit the damage, but Illinois made a solid effort to do just that and it made zero difference
https://support.google.com/googlenest/answer/9320885?hl=en
> Note: Disabling Face Match will delete your face model from your device but it will not delete the enrollment images used to create your face model. To delete Face Match enrollment images, visit myactivity.google.com.
So, the real question is, why do we have to be aware of some gotcha that's deeply embedded somewhere in some support page that majority of us won't look at? This is the case with most of Google's opt-out strategies.
This is a handy link to check from time to time. Note that some of these include degraded experience on Google's services, so I definitely wouldn't recommend turning them all off (or "pausing them", as Google puts it) without understanding what they actually do.
[0] https://myactivity.google.com/page?page=match_enrollment
> Can I opt out of all of these as well?
> Unfortunately, not very easily. With Google Photos, you can choose not to run the facial recognition tool on your own photos, but you can't control what other people who may have uploaded photos of you decide to do.
Sadly looking at reality it is too watered down.
Given that a Butlerian Jihad seems unlikely, what are our options? If we can't stop it, maybe we need to keep pace with it instead. If this is a Red Queen Race, then we need to give people the tools needed to compete.
I think it's mostly an emergent phenomena enslaving everyone into some cultural and behavioral paradigm that nobody intends or particularly wants.
But the costs of shutting down all these incentivizing/nudging/conditioning/addicting technologies would kill most of the tech sector (by market cap), and therefore can't be seriously entertained.
So the industry is too big to fail?
I couldn't care less if predatory companies collapse. None of the tech itself is inherently evil, its only being used against us instead of working for us. If google were disbanded or broken up today new companies would rise up continue to do what they do now under more responsible terms. Those companies can continue to provide cell phones and email accounts without using those things to build dossiers on the people who just want to communicate with friends and family.
Many people today think it's impossible to offer anything if you aren't abusing your users because that's all they know, but I remember when there were hundreds of free email providers long before it became technically feasible to read every last email stored on the server to spy on users.
I think that's a naive position to take. People are people, and human nature really is hard to fight. It's a virtual certainty that anything replacing google, will be violating your security and privacy. Especially if it's "free".
Companies are amoral monsters who care about nothing but making money and there will always be a struggle with regulation followed by deregulation followed by more regulation as people push back against abuse, but that cycle has kept things in relative order. Companies have gotten very good at inserting themselves into government, directly and indirectly, to stand in the way and prevent the people from keeping them in line, but I don't think it's entirely hopeless yet.
People care, they do, but the feedback loop from shiny feature to creeping authoritarianism is too long for monkey brains to grasp. What you call lazy, I call dopamine. You can't expect us naked apes to just ignore that hit. Change the game instead.
It's easy to blame it on "people". But if we put ourselves in a situation where we rely on us fallible beings swimming upstream day after day, on snowflakes feeling responsible for the avalanche, do we then really have anyone to blame but ourselves?
The players can't have a say on the rulings, and the refs shouldn't have an opinion on the winners. In other words, you're either in the game, or out, but never both.
I imagine a world where there's a very clear delineation between people who are currently in and currently out. When you're in, you go with the flow. You follow your heart, sing, dance, try to be happy, be creative. And when you're out, that shits a no go. You remember what it was like to be emotional, you empathize, but decisions must be strictly non-impulsive.
People take turns going from one side to the other. Too long on either side and you'd lose sight, ruin the game.
It's also kind of analogous to trip-sitters.
Bruce Sterling called that group "Zen Serotonin" in his novel Schismatreix[1] about posthuman ideologies. They enforced their "strictly non-impulsive" zen-like calm with biomonitor-regulated sci-fi drugs. They advocated strongly for social order and slowing the rate of social change.
My username ("pdkl95") is based on the opposite ideology. It is another sci-fi drug from Schismatrix, used by another ideological faction to force (often destructively, as brain damage) a change in perspective; it forces someone out of the comfortably familiar paradigm that Zen Serotonin tried to maintain.
This "clear delineation" between groups will eventually happen. All species eventually fracture into separate daughter-species. Instead of finding different ecological niches, human will speciate into different ideological niches.
“The best leaders are those the people hardly know exist.
The next best is a leader who is loved and praised.
Next comes the one who is feared.
The worst one is the leader that is despised.
If you don't trust the people,
they will become untrustworthy.
The best leaders value their words, and use them sparingly.
When she has accomplished her task,
the people say, "Amazing:
we did it, all by ourselves!"I bring these two up because: 1. Saying 1940's Nazis are monsters exemplifies a lack of empathy. They did monstrous things, no doubt, but the vast majority of the army was young men, doing a duty, during a depression, while under one of the first and strongest propaganda campaigns ever. They as people were very little different than us now. It's a prime example of how the road to hell can be paved with good intentions.
2. The way that every single time anyone implicates to even the slightest degree that maybe powerful people might be smart enough to do something subversive and tricky, people jump over each-other trying to be the first to make a tin-foil hat joke... that shit is annoying.
In conclusion, a society which managed to miss the whole "empathy" message of WW2 and actively undermines any attempt to pass blame towards the people in power is being extremely irresponsible, and the odds of things going badly are stacked against.
Apple earns billions yearly from their search deal with Google. Apple earns billions from sales of targeted ads.
Apple does not earn millions from the sales of targeted ads. Google does.
Apple earns millions from selling a link to Google.
They also want to provide their customers with access to the best search engine. I’m sure they’d prefer that not to come with ads, but that option is not for sale.
Claiming Apple earns the money from targeted ads is like saying Herman Miller or PG&E make money from targeted ads because they sell something to Google.
Obvious bad reasoning.
Google could make its money a different way.
It’s true that if they did so they might not be a monopolist.
Who knows what the bidding for the default search spot would look like in that case, but it is their choice.
To put an extreme example, just because Apple pays Foxconn does not mean they don't benefit from what's effectively slave labour. They're not removed from the effects of their transaction. The principal works in reverse too.
I dislike Google’s business model but I use google search amongst others because they have a monopoly.
If a competitor arose that Apple’s customers were happy with, I’m sure they’d prefer to choose a different company.
Steve Jobs once said in an interview with Wired:
> When you're young, you look at television and think, there's a conspiracy. The networks have conspired to dumb us down. But when you get a little older, you realize that's not true. The networks are in business to give people exactly what they want.
Sadly, I think that quote applies a lot to Google as well. I think a lot of people, and at least anecdotally almost everyone I talk to, just don't/doesn't care about (or maybe understand the threat of) the collection that is happening. In the case of Google, they just want to find stuff on the internet without trying multiple times or adding additional keywords to their search.
Apple’s business model is about providing the best experience to their users.
I'm dearly hoping this targeted stuff gets enough backlash / blockage that adtech companies give up on it, or that DuckDuckGo and other more privacy-respecting companies end up winning in the end.
This, along with the previous changes to make the photo capability be a short video capture that gets sent to Google, make me very suspicious about what they are doing with all of that data.
Things like the facial action coding system for microexpression analysis have been around for decades for anyone with a college library card. It's just been very difficult for software to parse from video. I can definitely see the camera changes making this a lot easier.
The issue here is the collection, storage, and potential use of the data by Google. Google should allow you to opt-in to them collecting that data anywhere off-device, but for now they do not.
With that said, the Richard Stallman in me still regrets giving Amazon the opportunity to capture HD video of me in meatspace that is linked to my customer profile.
I'm surprised it has taken this long to roll out, as I remember in the mid 90s one supermarket trialed it, but then they abandoned it, and twenty years later it's back.
IMO this gives most of the benefits (admittedly theft may be easier, but it's no different than regular shopping), but non of the they-are-tracking-everything-I-look-at privacy issues.
Self-checkout still requires things to come out of your bag, so the person who's there for when a self-checkout machine inevitably needs cashier assistance can be keeping an eye on several stations at a time.
With scan-and-go, those eyes need to be moved to the shelves, which is a much larger area and won't all be in one person's line-of-sight at once (and the person can easily obscure vision of the shelf).
I don't see how that could ever have been the case. Self-service replaces skilled labor (employee cashier) with unskilled labor (customer cashier.) Why would that ever be more efficient? When you throw in matters like needing to wait for an employee every time somebody buys liquor or cough syrup, it's clear self-service is doomed to be much slower.
It seems to me, self-service is actually designed to reduce labor costs for the store.
I see no conceivable upside. I totally get why companies are installing them; it's plain old greed. There is nothing complicated about that. But knowing that doesn't make me want to use them.
Apple Stores have had this since 2011. I'm not sure why it's taken so long for other stores to get on board.
Maybe the delay for supermarkets is that they operate on such small margins that upgrading technology takes a long time.
So much for apple keeping data private.
This is completely different from what the article implies - that Apple shares FaceID enrollment data with anyone who asks.
If Apple restricted access to that hardware, the internet would flip out and cry foul. So they allow it, with a lot of limitations, and people still try to make an issue of it.. sigh....
https://epic.org/privacy/white_house_consumer_privacy_.html Note. I don't know how i feel about EPIC so buyer beware. Yet sounds interesting.
Defaults matter. So when you want to use everyone's data, and you make it opt in, you only get a little bit of everyone's data, whereas if you make it opt out, you get most everyone's data. And unfortunately, legal regulation is the only way we can override tech companies desire to default to the best answer for them.
https://slate.com/technology/2018/04/why-arent-privacy-group...
your critic is more a matter of focus than agenda.
EFF is more focused on protocols and crypto and software per se. while usability, end user abuse etc is not high on it's priorities.
Serious question.
I don't know how you draw the line between what would have to be opt-in and what would have to be opt-out.
The underlying issue is that companies are shipping products that do a bunch of extra shit that nobody expects or can predict.
The solution is for companies to be transparent and open about what their products are actually doing, and then users can decide for themselves if they want to use them or not.
Yes, I want to opt-in explicitly, even for heart rate when I buy Fitbit. The default should be do not track, do not do anything without explicit permission from user. This includes even harmless features and core features of a product (like heart rate monitor for fitbit).
This wouldn't be the case if companies played nice. We are well past that now. We can't believe pretty much any company online, not to sell data, mess with their users' privacy etc.
Explicitly opting in is a minor inconvenience compared to destroying everyone's privacy.
I'm not at all affiliated with Reflectacles, but when i first heard of them (on HN) I loved the idea! Where else beyond Reflectacles can i throw my money at in order to preserve my privacy?
I meant: what other projects exist like Reflectacles that i could (either now or soon) happily pay money for (in order to help preserve privacy)?? For me, privacy is no longer a "nice to have" feature, but rather, a top-most feature for products/services that i pay for.
Your own server (physically in your home) running your own services. Enables you to access your data from your phone/laptop/desktop while retaining control.
As far as my own server, yep, I'm already running services like nextcloud, etc. My challenge is more on the hardware and other non-digital products/services.
But thanks for bringing up librem 5 - kudos!
The age of privacy is over.
What is Google photos? Isn't half the purpose of Google photos to be food for machine learning?
I am thinking about stopping it because I'm uncomfortable with Google having all that data. I'm going to look into any local and/or open source solutions in this space.
Share if you find anything. The only other solutions I've found so far are:
Apple Photos - requires having Apple devices
Plex - meets neither the 'local' nor 'open source' requirement as it sends your photos to some other random cloud provider to scan
If you can find anything, or if anyone else does know, please do share!
Your photos and videos remain on hardware that you own (or rent). It's designed to scale to millions of photos and videos on limited hardware (I run it for my family on a raspberry pi with a big external hard drive that sits next to my router). The browsing experience is fun, both on a 4k display and on my iPhone SE
The only cloud service I run is my licensing storefront, and delegate error reporting to Sentry, which you can opt out of.
Disclaimer: I'm the founder and developer.
I just don't trust myself enough to not fuck up and lose all my photos if I self hosted something that was equal. I run a small home lab and I never store anything on it I cannot afford to lose.
Blew my mind when I first saw they had added it.
You have to tag your pets (I think it'll prompt you at some point, or IIRC you can tap your pet's face) and name them, but after that it'll also create an auto-category (label? album? Whatever) for each pet.
Super cool stuff.
The iPhone was able to complete all of those searches without sending my data to Apple. When companies like Google say they have to have a copy of your pictures, they are lying.
> When companies like Google say they have to have a copy of your pictures, they are lying.
Did Google actually say that? I think they just built a product with different trade-offs than Apple Photos.
The phone automatically offloads the full-resolution images to iCloud while retaining thumbnails and metadata. The photos on iCloud are encrypted so that even Apple can't see them.
Moving the goalposts doesn't change the fact that everything you want can be done on-device, with none of the privacy-destroying methods that Google has imposed on the world.
You could always just...not use/buy their products
If I, random delivery man, walk up to a Nest user's home, and his camera scans my face to compare to the data stored for facial confirmation, that this information is not used/stored by the recognition software?
The system is always on/scanning. It's using my face somehow, and I'm not using or buying their product, I'm just a person going about my day.
Or to a business with a security camera.
And as for the delivery man angle... sure, that may seem like compulsion, but for one thing, the delivery man can always quit his job (especially in an optimally functioning market which will of course increase labor opportunities and will definitely not reduce wages for labor to its marginal production costs), plus eventually they'll have to quit because we're going to automate delivery anyway.
Doorbell cameras give perfectly adequate views of many places other than people's porches.
If Google wants to put a data-collecting robot on the street with a big sign reading "We're scanning your face to sell to advertisers!" there's nothing I can do about it, but at least it's honest.
Google using Nest cameras to scan the activities of people just walking down a nearby street is not cool.
If I remember correctly, Nest is a thermostat. Not sure what a camera is for in my thermostat, but so Google is indexing your face only if you bought a device of theirs with a camera and installed it in your home? Not that that makes it much better (imagine your Google Play Services suddenly figured this would be helpful to you and makes it opt-out), but the current title implies it indexes all faces on image search or maybe pictures on their file upload system or something.
In one comment you made an incorrect assumption about what the product is, what Google is doing, proposed an imaginary situation about them doing something even worse and then drew a wild inference based on the title of the article.
Can I opt out of all of these as well? Unfortunately, not very easily. With Google Photos, you can choose not to run the facial recognition tool on your own photos, but you can't control what other people who may have uploaded photos of you decide to do.
Facebook just recently switched to an opt-in setting for allowing its software to suggest friends tag you in their photo posts, meaning the social network will no longer make such suggestions by default. But that doesn't mean Facebook isn't scanning or processing your image, only that it won't share that information with other users unless you choose to allow it.
Welcome to the era of living publicly and naked. Enjoy.
I can spend all the energy I want to not use their products or limit the amount of data that I have, but the second someone else uses it (that I communicate with, has photos of me, etc) and gives them unlimited access they know more about me than I consent to.
It is simply ignorant to tell me I can vote with my wallet, I would have to cut social ties and move into the wilderness to escape these abusive information-gathering practices.
HN has no protection to stop me from putting my friend's email here (see@example.com) and you don't go after HN for that. You'd go after me for sharing your details.
My biggest issue comes from where the processing is being done. If it was 100% on device I would be more ok with it. Same for processing photos and anything else that needs to be done with my data.
But most companies instead ship all of your (and other people's data you happen to have) to their servers.
For Google Photos, what can other people who have uploaded photos of me do by enabling facial recognition on them? How is that facial recognition data used by Google?
I don't understand why these articles don't even bother with a slightly more in-depth reporting, instead of just pivoting to the next bugaboo, namely Facebook.